Maksymilian Arciemowicz has discovered multiple variable injection vulnerabilities that can be exploited through "$cfg" and "GLOBALS" variables and localized strings

It is possible to force phpMyAdmin to disclose information in error messages

Failure to correctly escape special characters

Impact

By sending a specially-crafted request, an attacker can include and execute arbitrary PHP code or cause path information disclosure. Furthermore the XSS issue allows an attacker to inject malicious script code, potentially compromising the victim's browser. Lastly the improper escaping of special characters results in unintended privilege settings for MySQL.